VYPR
Vendor

OX App Suite

Products
4
CVEs
79
Across products
80
Status
Private

Products

4

Recent CVEs

79
View all 79 CVEs →
  • CVE-2022-29851CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.04

    documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document that is disguised as a PDF document.

  • CVE-2022-24405CriJul 27, 2022
    risk 0.64cvss 9.8epss 0.03

    OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.

  • CVE-2020-12645CriAug 31, 2020
    risk 0.64cvss 9.8epss 0.01

    OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption.

  • CVE-2019-7158CriJun 17, 2019
    risk 0.64cvss 9.8epss 0.02

    OX App Suite 7.10.0 and earlier has Incorrect Access Control.

  • CVE-2019-14226HigOct 14, 2019
    risk 0.53cvss 8.1epss 0.01

    OX App Suite through 7.10.2 has Insecure Permissions.

  • CVE-2020-8543HigJun 16, 2020
    risk 0.49cvss 7.5epss 0.02

    OX App Suite through 7.10.3 has Improper Input Validation.

  • CVE-2023-41706MedFeb 12, 2024
    risk 0.42cvss 6.5epss 0.01

    Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing…

  • CVE-2023-41705MedFeb 12, 2024
    risk 0.42cvss 6.5epss 0.01

    Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of DAV user-agents now gets monitored, and the related request is…

  • CVE-2023-24603MedMay 29, 2023
    risk 0.42cvss 6.5epss 0.01

    OX App Suite before backend 7.10.6-rev37 does not check size limits when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of data.

  • CVE-2022-24406MedJul 27, 2022
    risk 0.42cvss 6.5epss 0.01

    OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Documentconverter API calls.

  • CVE-2021-33491MedNov 22, 2021
    risk 0.42cvss 6.5epss 0.03

    OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records.

  • CVE-2020-28943MedApr 30, 2021
    risk 0.42cvss 6.5epss 0.01

    OX App Suite 7.10.4 and earlier allows SSRF via a snippet.

  • CVE-2021-23927MedJan 12, 2021
    risk 0.42cvss 6.4epss 0.01

    OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request.

  • CVE-2020-8544MedJun 16, 2020
    risk 0.42cvss 6.5epss 0.01

    OX App Suite through 7.10.3 allows SSRF.

  • CVE-2018-12609MedJan 30, 2019
    risk 0.42cvss 6.5epss 0.01

    OX App Suite 7.8.4 and earlier allows Server-Side Request Forgery.

  • CVE-2023-24602MedMay 29, 2023
    risk 0.40cvss 6.1epss 0.00

    OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title.

  • CVE-2023-24601MedMay 29, 2023
    risk 0.40cvss 6.1epss 0.00

    OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree.

  • CVE-2022-37306MedApr 16, 2023
    risk 0.40cvss 6.1epss 0.01

    OX App Suite before 7.10.6-rev30 allows XSS via an upsell trigger.

  • CVE-2022-43697MedApr 15, 2023
    risk 0.40cvss 6.1epss 0.00

    OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob.

  • CVE-2022-43696MedApr 15, 2023
    risk 0.40cvss 6.1epss 0.00

    OX App Suite before 7.10.6-rev20 allows XSS via upsell ads.